Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
13.689 exploits
GitHub PoC1
Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH23 mai 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
yuansec/CVE-2024-4323-dos_poc
CVE-2024-4323CRITICAL22 mai 2024
Fluent Bit Memory Corruption Vulnerability
53RISCO
abrir
GitHub PoC
Proof Of Concept for the CVE-2016-10033 (PHPMailer)
CVE-2016-10033CRITICALsob ataque22 mai 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC
Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094
CVE-2024-3094CRITICAL22 mai 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
bfengj/CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC2
bfengj/CVE-2024-32002-Exploit
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
1mxml/CVE-2024-32002-poc
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
Repo for testing CVE-2024-32002
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC4
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
CVE-2024-32459CRITICAL22 mai 2024
FreeRDP Out-Of-Bounds Read in ncrush_decompress
48RISCO
abrir
GitHub PoC
CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
This is the main repository for CVE 2024-32002, and requires recursive cloning because it contains the submodels necessary for execution.
CVE-2024-32002CRITICAL22 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC11
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
CVE-2024-4367MEDIUM22 mai 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC4
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM22 mai 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
This script checks if a target host is vulnerable to CVE-2023-34992 by sending a crafted payload to the FortiSIEM appliance. It then analyzes the response to determine if the host is vulnerable.
CVE-2023-34992CRITICAL21 mai 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir
GitHub PoC3
Patch your D-Link device affected by CVE-2024-3272
CVE-2024-3272CRITICALsob ataque21 mai 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RISCO
abrir
GitHub PoC6
Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo con precaución en entornos controlados y solo con fines educativos o de pruebas de seguridad.
CVE-2024-32002CRITICAL21 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC2
CVE-2019-3396 Memshell for Behinder
CVE-2019-3396CRITICALsob ataqueransomware21 mai 2024
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC1
Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.
CVE-2024-4323CRITICAL21 mai 2024
Fluent Bit Memory Corruption Vulnerability
53RISCO
abrir
GitHub PoC
CVE-2024-32002 POC
CVE-2024-32002CRITICAL21 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
Este script está creado para mostar usuarios de DVR, VULNERABILIDAD (CVE-2018-9995)
CVE-2018-999521 mai 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
Securenetology/CVE-2013-3900
CVE-2013-3900MEDIUMsob ataque21 mai 2024
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
CVE-2024-32002 hook POC
CVE-2024-32002CRITICAL21 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC140
Time Based SQL Injection in Zabbix Server Audit Log --> RCE
CVE-2024-22120CRITICAL20 mai 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir
GitHub PoC203
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
CVE-2024-4367MEDIUM20 mai 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC57
CVE-2024-4367 arbitrary js execution in pdf js
CVE-2024-4367MEDIUM20 mai 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC1
CrackerCat/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC3
jweny/CVE-2024-32002_HOOK
CVE-2024-32002CRITICAL20 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC15
This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code execution.
CVE-2024-4323CRITICAL20 mai 2024
Fluent Bit Memory Corruption Vulnerability
53RISCO
abrir
GitHub PoC3
jweny/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
CVE-2024-32002-hook
CVE-2024-32002CRITICAL20 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
anteriorpágina 225 / 457próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.